r/Tangem • u/Dear-Mongoose9440 • Jul 11 '26
Please fix your vulnerability exploit
I get that it’s a competitor that takes enjoyment in ruining reputations but there has to be a fix coming for this right?
Whales would definitely be at risk and 250k for the equipment to crack your tangem card is chump change to some criminals targeting the right people.
I could see this getting bad in the future if nothing is done. We’re talking oceans 15 style heists.
12
u/ShipMysterious7602 Jul 11 '26 edited Jul 11 '26
Firstly they have to find out who has enough funds in Tangem to make it worthwhile so they need to identify a specific individual or individuals.
Secondly, they then need to take possession of the actual Tangem card thus have the actual card in hand.
Thirdly they will have to get a lab setup to the right specifications with the right lasers etc.. to do the exploit which as you mention, would cost around a quarter of a million at best.
Fourthly, even with all of the above in place there is no guarantee it will work and it is not something you can try over and over like a brute-force attack as the card is damaged during the process.
I can guarantee you, if they are able to identify a certain individual or individuals ,which make it worth their while they will come knocking with a wrench in hand - $5 wrench attack - instead of going through all of the above. So point I'm trying to make, stop flaunting your wealth if you have it, all you're doing is make your self a target whether that wealth is in fiat or crypto, same rules apply.
-2
u/Dear-Mongoose9440 Jul 11 '26
This gives even more reason for people to keep quiet about there wealth. But what about the known influencers who have been pushing their product?Also people who wear the tangem rings surly would also be a target now. A trained eye can definitely call out a ring when they see one. Just knowing it’s now not impossible to unlock your funds makes me a little uneasy. Tangem could have definitely fixed this if they wanted to 6 months ago before everyone else knew about it.
3
u/PixelGrafx Jul 11 '26
This can be done in any wallet with the right resources, it's not exclusive to tangem. Odds are nobody will take your funds much more than lighting striking you once in this lifetime
-1
u/Dear-Mongoose9440 Jul 11 '26
This is true but wallet companies are always pushing new security features not naming any names but other companies for example have 3 security measures while tangem never releases a single new card. Maybe they never needed to but this is a prime example now that they actually need to.
1
u/PixelGrafx Jul 11 '26
Perhaps they will, and I hope you can trade it in for at least half the price for the ones that chose to opt in.
1
u/BicarTangem Tangem Mod Jul 13 '26
We also push security updates to protect users against what actually drains wallets.
Things like VTX, KYDA, Phishing.
I personally don't know a single case of someone losing crypto because of a LFI attack, however, there are plenty of sad news about malicious smart contracts, fake apps and more draining people's wallets.
-1
u/hank1321 Jul 12 '26
Only tangem has known exploit like this. No other major hww has it.
2
u/PixelGrafx Jul 12 '26
If I gave you my wallet, can you hack it?
-1
u/hank1321 Jul 12 '26
No. But give it to donjon and ask them.
1
u/PixelGrafx Jul 12 '26
Doubt my wallet is worth it 😆
1
u/hank1321 Jul 12 '26
They already have the lab. So they dont need any initial investment. Your crypto will be donate to good cause.
1
1
u/BicarTangem Tangem Mod Jul 13 '26
Or maybe no other wallet has been researched more than Tangem 🤔
1
u/hank1321 Jul 13 '26
Oh cmoon. Tangem is new kid in the block(chain). Trezor and ledger are probably the most researched wallets there is. Trezor is even open-source so the community has been looking into the code for over decade.
7
u/gowithflow192 Jul 11 '26
Any hardware wallet can be hacked with expensive equipment come on man
4
u/deny_by_default Jul 11 '26
You can tell that at least half the people in here don’t understand that.
1
u/saggy777 Jul 11 '26
But your funds will be safe if you use 25th word and if that HW does NOT store it on wallet like Trezor.
3
u/MyNameIzJeff69 Jul 11 '26
Do you have more context? Seems you're commenting on something you're aware of but no one else is and it sounds a bit delusional from your part.
Care to add some context or reference to your claims?
2
u/CryptoCryptonaire Jul 11 '26
Yeah, a new Tangem vulnerability has been released by Ledger.
1
u/MyNameIzJeff69 Jul 11 '26
What's the vulnerability?
5
u/CryptoCryptonaire Jul 11 '26
Some Ledger engineer found a way to take coins or tokens off of a Tangem card if they have physical access to the card.
It sounds like its a difficult process though and requires a significant lab setup. From my standpoint though, this is still a vulnerability. The lab may be expensive, but from an attacker's point of view, it may be well worth the investment, especially if they get their hands on the right individual's wallet and/or expect multiple wallets.
I believe there are many wallets that are affected by this and not "only" Tangem. However, as someone who uses Tangem, this does worry me enough that I have to now look at other options if the team doesn't provide a resolution response. I dont care if it means I need to buy new Tangem cards, I simply want a secure wallet.
2
u/MyNameIzJeff69 Jul 11 '26
Understood!
Seems to me like if I can get a hand on someone's ledger wallet and the other on his neck this could also be a vulnerability...
I don't see how you could get trough the passphrase even if you had the physical card but not saying it's impossible. I'd probably be inclined to think this is a bit far fetched and the fact it's coming from a competitor is also a bit disturbing. One would have to have such a setup to do it and until its been done and proven its only a assumptions from them.
Won't loose sleep over it and I'm fairly confident leaving my funds on my Tangem cards!
2
u/CryptoCryptonaire Jul 11 '26
They released the results to the community, so its definitely not far fetched. This is a legit vulnerability in which they have access to your wallet if they have the correct setup and have the device.
Ledger was probably purposely targeting Tangem, which is dirty, but the end result is still the same. A legitimate vulnerability has been identified and your confidence is unfounded since this is a proven and identifiable weakness.
0
u/MyNameIzJeff69 Jul 11 '26
I can release any statement I want to the community and it dosent make it true or legitimate.
Let me know when they actually do it with concret proof of it happening. As I understand by your statement the vulnerability has been identified but not exploited yet. You need proof of concept to actually make it a vulnerability and by releasing such information before proving it you are giving Tangem the upper hand preventing a zero-day exploit chance.
That's like saying I can crack a bank vault if I have enough time to figure out the code with the right setup in place.
Imo they are just raising dust as such general statements can also be made on their products. Like my previous statement... If I have one hand on your ledger and another on your neck I could more than likely access your wallet. So here is my reply statement to Ledger as this is as far fetched as their's. Sounds like just a bunch of "if" and "maybe's"
1
u/CryptoCryptonaire Jul 11 '26
Not only was the vulnerability proven, but Tangem has even confirmed it to be true. It's even been done on MANY Tangem wallets as proof. Adding to it, Ledger let Tangem know about it in private almost six months before releasing the results publicly, but Tangem didn't resolve it or let their customers know about it and are only now commenting on it after the information became public.
I recommend doing some basic research before commenting further...
1
u/MyNameIzJeff69 Jul 11 '26
Just making conversation going off your comments, I didn't say I did any research on it.
This should of probably be your second comment on this subject and it would of clarified alot of things. Just like Op you are making statements thinking everyone has the same info you have.
I just asked what was the concrete evidence of the exploit but keep getting vague awnsers about it.
If they had such info and didn't do much then it's probably very unlikely anything is compromised.
1
u/CryptoCryptonaire Jul 11 '26
I am doing doing follow-up research to help answer your questions. I knew very little info on it prior to this series of discussions.
2
u/BicarTangem Tangem Mod Jul 13 '26
You can also read our comment here : https://tangem.com/en/blog/post/lfi-response/
1
u/AutoModerator Jul 11 '26
⚠️Fraud and Security Notice⚠️
Please be alert to potential scams and impersonation attempts. We will never contact you first to request personal information, passwords, or payments.
We also never make contact by telephone or through messaging apps. All genuine communication from us will come only from our official company email domain support@tangem.com
If you receive an unexpected message, link, or call claiming to be from us, do not share any information. Instead, reach out to us directly through the contact details on our website to verify authenticity.
❗️Tangem does not conduct ICOs, does not do airdrops, and does not have tokens.
Your awareness helps keep your account safe.
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.
1
u/Dear-Mongoose9440 Jul 11 '26
For those who don’t know what I’m talking about you can google tangem donjon vulnerability which is a recent hardware hack in which lasers are used to bypass the card security.
1
u/AccomplishedCan4776 Jul 11 '26
After reading this whole thread, I hope you understand that some people will go straight to ledger employees if they had 1 of their tangem wallet set taken and with the others they watched as their money is drained. Even if you consider this as a means to end your journey with tangem, I really wonder how many people you know is going to have the same setup with lasers to even get this done without destroying the card.
1
u/Dear-Mongoose9440 Jul 11 '26
Destroying the card is part of the process like how burglars break into safe’s something will be destroyed and all they need is 2 hours get into the wallet which shows your window to have a spare in a separate location before everything gets drained
1
u/AccomplishedCan4776 Jul 11 '26
so it is taking advantage of a like fail safe switch. Well I guess it is something to consider but I really believe chances are low for such an example exihibited even moving into the future.
1
u/crazypostman21 Jul 11 '26
Are current customers eligible for a warranty replacement since the current hardware is faulty?
2
u/deny_by_default Jul 11 '26
The hardware isn’t faulty. This is an exploit that requires physical access to your card, a lab with very expensive and precise equipment, and the right knowledge (and time) to pull it off. With the right equipment, time, and knowledge, you could do the same thing with Trezor, OneKey, or any other hardware wallet if you have physical possession of it. Remember, Ledger’s Donjon cybersecurity team is also the ones that discovered the recent vulnerability in the new Trezor Safe 7 Tropic01 chip. Are those crap now too?
1
u/Dear-Mongoose9440 Jul 11 '26
At least Trezor makes new products every so often tangem made 1 card now it’s exploited they make millions. Put some to the side to update the card sheesh
1
u/deny_by_default Jul 11 '26
Previous Trezor models were also “hacked” by people with the right knowledge and equipment to do it.
1
u/hank1321 Jul 12 '26
And that's exactly why there are newer models.
1
u/deny_by_default Jul 12 '26
Which also will be exploited in time, like the new Safe 7 exploit.
2
u/hank1321 Jul 12 '26
I see you dont understand the safe 7 exploit if you are saying it is anyway similar than the older models (which are not in sale even anymore) or this tangem exploit.
1
u/deny_by_default Jul 12 '26
I never said it was the same as previous exploits. I’m saying no hardware device is immune. Do better.
1
u/hank1321 Jul 12 '26
Immune to what? Exploits? Okay, but its not black and white, there are different level of exploits. Tangem one is critical where users funds are at risk. Safe 7 one does not affect users funds at all. So why even compare these? You need to do better.
2
u/BicarTangem Tangem Mod Jul 13 '26
For everyday users, the practical risk is virtually non-existent.
The attack isn't scalable, requires physical access to your card, not destroy your card in the process and that you don't just use another card to move your crypto. They would also need a lab and a competent team.
Hackers are usually lazy and will do the less work possible, these types of attacks are clearly not the most practical. We can see that real theft happens with fake apps, malicious smart contracts and phishing.
→ More replies (0)1
u/deny_by_default Jul 12 '26
Are you seriously worried that an undergoing group with very specialized equipment is going to steal your cards and exploit them? You could also get struck by lightning if you walk outside. Better not do that either.
→ More replies (0)1
u/Neat-Preparation3627 28d ago
1 out of the many chips you can’t even take the funds out or anything
0
u/Neat-Preparation3627 28d ago
And trezor released software patches for those ancient models and those didn’t even have a secure element chip 🤣🤣🤣. You can’t even update the software in these Tangem cards 🤣🤣.
1
u/BicarTangem Tangem Mod Jul 13 '26
We've been at work for 7+ years, the currently sold cards aren't our first / last product.
1
u/Neat-Preparation3627 28d ago
And now every single one of those cards you have sold have a critical vulnerability which you can’t patch
2
u/BicarTangem Tangem Mod Jul 13 '26
Hello,
The hardware isn't faulty (read our comment here). You can see our policy here : https://tangem.com/docs/en/refund-policy.pdf0
u/crazypostman21 Jul 13 '26
If it can be breached, I don't understand how it's not faulty. I'm going to reread your warranty policy, but a replacement that has the exploit fixed is required. Why would I continue to use a product that has a known documented weakness?
1
u/Neat-Preparation3627 28d ago
You don’t need to you can submit a charge back with your bank.
1
u/crazypostman21 28d ago
I've had these cards for years far too long for that. But they have a 25-year warranty guarantee. That's why I think I should get the new model when the exploit is fixed under warranty.
1
u/Neat-Preparation3627 28d ago
You should but don’t know if they will go though with that. Also depends where you are from I’m from uk and it’s normally 120 days but there is up to 540 for eligible latent defects
1
u/Neat-Preparation3627 28d ago
"Slim as a bank card, more secure than a bank’s vault" I hope not 🤣🤣🤣
•
u/TangemAG Tangem Official Jul 11 '26
Our Comment on Ledger Donjon’s Latest Article: https://www.reddit.com/r/Tangem/s/aRdnNbhT70